AI Weekly Malaysia

Back to items Summaries

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

ID
20266
Status
summarized
Published
01 Sep 2026, 9:08 PM
Fetched
01 Sep 2026, 10:56 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
6.5
Created
01 Sep 2026, 10:58 PM
Tags
Audience
developersvibe_coders

What happened

Iranian hacking group Nimbus Manticore is delivering cross-platform RATs (NodeRabbit and PollCat) by posing as recruiters on LinkedIn and sending developers trojanized coding challenge ZIP files. The malware, written in Node.js and obfuscated JavaScript, targets Linux and macOS systems and was first found on a machine in Afghanistan, with subsequent sightings in Egypt and Ethiopia. The attack ZIP ('Front-Technical-Challenge.zip') contains a fake project management tool called Taskflow and is hosted on AWS.

Why it matters

If you or your team receive coding challenges or technical assignments from recruiters via LinkedIn, verify the recruiter's identity through official company channels before downloading and running any ZIP archives. This attack specifically targets software engineers through a workflow they encounter routinely, and the malware is cross-platform—meaning macOS and Linux developers are not immune.

Discussion angle

How should teams handle take-home coding challenges from external recruiters—what's a practical verification protocol before running unknown code on your dev machine?

Top